Skip to content

Security1 publisher2 min readPublished

White House order makes Login.gov the one sign-in for America.gov's federal services

White House order routes federal services with over 100,000 yearly users through America.gov, using Login.gov as the one sign-in. Agencies keep custody of their records, so what gets concentrated is one credential that reaches every connected service.

The Watch · Security desk

Illustration accompanying White House order makes Login.gov the one sign-in for America.gov's federal services

What happened

  • Agency heads must identify their covered services and connect them to America.gov, including through public APIs, dashboards and digital forms.
  • America.gov is meant to let a signed-in person ask questions in plain language and, where authorized, complete government transactions without visiting agency sites.
  • IRS tax filing and services of the Department of War and intelligence agencies are excluded, and OMB's director can add or drop covered services by memo.
  • OMB has 90 days from the order to send agency heads a memorandum on how to implement it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision OMB now has to set how often America.gov re-verifies identity before a sensitive transaction, because the order's aim of fewer identity proofs works against its own demand for secure authentication.
  • constraint The no-central-records rule means a breach of America.gov should not produce a bulk store of citizen data, as long as the relay layer does not keep copies of agency responses.
  • precedent OMB can add covered services by memo, so the number of agencies reachable through one hijacked account can grow without another executive order.

None of this changes what an attacker can do this week. America.gov has to be built first, and the rules for building it depend on the OMB memorandum [8].

The order starts from a complaint about repetition. Americans, it says, "repeatedly prove their identities to a Government that may already possess the information necessary to serve them" [10]. With fewer proofs, each one opens more. Login.gov is to be the authentication service [3] for a single point of entry [2]. That makes one Login.gov account the credential for every covered service connected behind it [1]. Whoever takes that account over gets the owner's reach across every one of those agencies [1].

The data side of the design is different. The order directs that each agency keep "custody and control of its records, systems, statutory responsibilities, and adjudicatory authority" [6]. It also says unifying access to federal services "does not create a centralized Federal system of records concerning the American people" [6]. It calls for data minimization as well [7]. Taken at its word, the order pools two things: authentication, and the layer that passes requests to agency interfaces. It does not pool the records. Whether America.gov keeps copies of what those interfaces return is left for the implementation memo to settle [8].

The front end also puts a model in the path. The order requires the super intelligence used with America.gov to be "accurate, reliable, and transparent" [12]. If a model can move a signed-in user's transaction forward, each of its actions has to be authorized and logged as that user's. The order's policy list names this requirement "auditable authorization" [7].

The older channels stay. In-person, telephone, mail and agency-specific digital services remain available, so America.gov "does not become the only option" [13]. A person locked out of a hijacked Login.gov account still has another way to reach the service [13].

What to watch

  • The OMB implementation memo, and whether it requires fresh identity checks before America.gov completes sensitive transactions.
  • Whether guidance lets America.gov store data returned by agency APIs, measured against the order's bar on a central system of records.
  • Any OMB memo that adds services to the covered list.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories